Microservice Banking
┌───────────────────────────────────────────┐
│ Internet │
└───────────────▲───────────────────────────┘
│ (HTTPS/HTTP)
│
[ AWS NLB on EKS / LB on Minikube ]
│
┌──────────┴──────────┐
│ Envoy Gateway (DP) │ ← Gateway API (Gateway/HTTPRoute)
└──────────┬──────────┘
│
┌────────────────────┼─────────────────────┐
│ │ │
│ (ext_authz check) │ (routes to backend) │
▼ ▼ ▼
┌────────────────┐ ┌─────────────────┐ ┌─────────────────┐
│ AuthZ Service │ │ orders-service │ │ inventory-service│
│ (Spring Boot) │ │ (Spring Boot) │ │ (Spring Boot) │
│ /authz/check │ │ ClusterIP Svc │ │ ClusterIP Svc │
└───────┬────────┘ └────────┬────────┘ └────────┬────────┘
│ │ │
│ │ │
│ (east–west calls via K8s Service DNS)
│ │ │
│ lb://orders-service lb://inventory-service
│ │ │
│ ┌────────▼────────┐ ┌─────────▼───────┐
│ │ Spring Cloud │ │ Spring Cloud │
│ │ K8s Discovery │ │ K8s Discovery │
│ │ + LoadBalancer │ │ + LoadBalancer │
│ └────────┬────────┘ └─────────┬────────┘
│ │ │
│ (K8s API: Services/Endpoints) │
│ │ │
┌───────▼────────────────────────────────────────────────────────┐
│ Kubernetes Control Plane (API Server) │
│ - Service registry (Services/Endpoints) │
│ - ConfigMaps/Secrets (app config & creds) │
└────────────────────────────────────────────────────────────────┘
Observability & Platform Add-ons (same in Minikube/EKS)
──────────────────────────────────────────────────────────────────────────────────
┌────────────────┐ ┌──────────────────────┐ ┌─────────────────────┐
│ Prometheus │ ←── │ Spring Actuator/Mtrx │ ─→ │ Grafana Dashboards │
└────────────────┘ └──────────────────────┘ └─────────────────────┘
▲
│ OTLP (traces/metrics/logs)
┌──────────────────────────┐
│ OpenTelemetry Collector │ ← Envoy & Spring apps export OTLP
└──────────────────────────┘
Security Flow (simplified)
──────────────────────────────────────────────────────────────────────────────────
1) Client → Envoy Gateway (JWT in Authorization header)
2) Envoy validates JWT (issuer/JWKS) [optional during Minikube bring-up]
3) Envoy → AuthZ Service: POST /authz/check (method, path, claims) → 200/401/403
4) If allowed → Envoy forwards to target backend Service (orders-service, etc.)
5) Services also run Spring Security (resource server) for defense-in-depth
Namespaces (example)
──────────────────────────────────────────────────────────────────────────────────
- platform: Envoy Gateway + Gateway/HTTPRoute (+ TLS secret/cert)
- security: AuthZ Service (your Spring “security repo”)
- apps: Business services (orders, inventory, …)
- observability: Prometheus, Grafana, OTEL Collector, Loki/ELK (optional)
Minikube → EKS migration notes
──────────────────────────────────────────────────────────────────────────────────
- Replace Minikube LB with AWS NLB via Service annotations (no app changes)
- Add cert-manager/ACM for real TLS certs and switch Gateway listener to HTTPS:443
- Install AWS Load Balancer Controller (provisions the NLB from your Service)
- Keep the same Gateway/HTTPRoute/SecurityPolicy manifests
Loadbalance
awesome — here are two tiny ASCII diagrams showing who load-balances where.
1) North–South (internet → cluster): Envoy does the LB
Client
│ HTTPS
▼
[ Envoy Gateway ] ← Gateway API (Gateway/HTTPRoute), JWT, ext_authz
│ │
│ (LB: picks a pod behind the K8s Service)
│ ▼
│ [orders-service Service (ClusterIP)]
│ ├────► pod A (orders-abc)
│ └────► pod B (orders-def)
│ ^ round-robin / least-requests (Envoy)
▼
Response
Envoy balances across pods for the target Service.
Policy like round-robin / least-requests is configured on Envoy (via its CRDs).
2) East–West (service → service): Spring does the LB
orders-service (Spring Boot)
│ calls lb://inventory-service
│
│ (Spring Cloud Kubernetes DiscoveryClient)
│ → queries K8s API for Endpoints of "inventory-service"
│
│ (Spring Cloud LoadBalancer)
│ → picks a pod (client-side LB)
│
├────► pod A (inventory-xyz)
└────► pod B (inventory-pqr)
^ round-robin by default (Spring)
Inside the cluster, Spring Cloud LoadBalancer picks the pod (client-side).
No Envoy needed for these internal calls (unless you later add a mesh).
Quick mental map
External traffic: Envoy = reverse proxy + auth + server-side LB.
Internal service calls: Spring Cloud DiscoveryClient + LoadBalancer = client-side LB.
Want me to add a third variant showing both at once (client hits Envoy → orders → inventory), with timeouts/retries labeled?


